用对抗演化框架提升工控系统自适应防御能力
Autonomous Cyber Resilience via a Co-Evolutionary Arms Race within a Fortified Digital Twin Sandbox
- 红蓝双智能体在加固数字孪生中持续对抗演化
- 新攻击检测F1得分从0.65升至0.89,延迟降至210秒
- 适合关注工业安全动态防御的研究者与工程师
信息技术与运营技术的融合使工业控制系统面临具备自适应能力的智能威胁,静态防御已失效。本文提出对抗韧性协同演化(ARC)框架,解决模型保真度、数据完整性和分析韧性构成的“信任三要素”问题。ARC在加固型安全数字孪生(F-SCDT)中构建红蓝双智能体的协同演化攻防机制:基于深度强化学习的“红队智能体”自主发现攻击路径,基于集成学习的“蓝队智能体”持续强化防御。在田纳西东曼过程(TEP)和安全水处理(SWaT)测试平台上的实验表明,对新型攻击的检测性能显著提升,F1分数由0.65增至0.89,检测延迟从超过1200秒降至210秒。全面消融实验显示,协同演化机制本身贡献了27%的性能提升。通过引入可解释AI并提出联邦式ARC架构,本工作推动了关键基础设施安全向动态、自我进化范式的必要转变。
原文摘要 · Abstract (English)
The convergence of Information Technology and Operational Technology has exposed Industrial Control Systems to adaptive, intelligent adversaries that render static defenses obsolete. This paper introduces the Adversarial Resilience Co-evolution (ARC) framework, addressing the "Trinity of Trust" comprising model fidelity, data integrity, and analytical resilience. ARC establishes a co-evolutionary arms race within a Fortified Secure Digital Twin (F-SCDT), where a Deep Reinforcement Learning "Red Agent" autonomously discovers attack paths while an ensemble-based "Blue Agent" is continuously hardened against these threats. Experimental validation on the Tennessee Eastman Process (TEP) and Secure Water Treatment (SWaT) testbeds demonstrates superior performance in detecting novel attacks, with F1-scores improving from 0.65 to 0.89 and detection latency reduced from over 1200 seconds to 210 seconds. A comprehensive ablation study reveals that the co-evolutionary process itself contributes a 27% performance improvement. By integrating Explainable AI and proposing a Federated ARC architecture, this work presents a necessary paradigm shift toward dynamic, self-improving security for critical infrastructure.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。